# US Indicts Russian Bulletproof Hosting Operators Behind Widespread Cybercrime Infrastructure


The Justice Department unsealed charges against three Russian nationals and their companies for operating ML.Cloud and Media Land — services that harbored phishing schemes, ransomware operations, and state-sponsored attacks across dozens of American targets.


## The Indictment


On Tuesday, July 15, 2026, the US Justice Department unsealed a December 2024 indictment charging three Russian nationals and two companies with operating criminal hosting infrastructure. The defendants are:


  • Aleksandr Alexandrovich Volosovik
  • Kirill Andreevich Zatolokin
  • Yulia Pankova

  • The companies they allegedly operated are ML.Cloud and Media Land — criminal hosting services that maintained infrastructure across multiple countries including China, the Netherlands, Finland, and the United States.


    The charges represent a rare case of Russian cybercriminals facing prosecution in the US, though authorities acknowledge that extradition remains unlikely. The DOJ has announced a reward of up to $10 million and potential relocation assistance for information leading to the arrests or conviction of the operators.


    ## Background and Context


    Bulletproof hosting is a well-established criminal infrastructure business model. These services intentionally shield illegal activity by:


  • Operating across multiple jurisdictions with weak cybercrime enforcement
  • Ignoring abuse complaints from victims and legitimate law enforcement
  • Maintaining infrastructure designed to survive takedown attempts
  • Accepting payment from any customer regardless of intended use

  • ML.Cloud and Media Land operated for years before sanctions in late 2025 and now criminal charges. The infrastructure was used indiscriminately — supporting profit-driven ransomware gangs, state-sponsored espionage units, phishing operations, and marketplace forums where stolen data and attack tools changed hands.


    According to the indictment, at least 42 entities across 21 US states were targeted through infrastructure hosted on these services, collectively suffering tens of millions of dollars in losses. The breadth of victims suggests these platforms functioned as critical backbone services for a significant portion of Russian-origin cybercriminal activity.


    ## How the Operations Worked


    The two companies provided hosting services explicitly designed to evade law enforcement and security firm takedowns. Common features of bulletproof hosting include:


    | Feature | Purpose |

    |---------|---------|

    | Multi-jurisdiction infrastructure | Complicates coordinated law enforcement action |

    | Resiliency protocols | Rapid failover to avoid service disruption |

    | "Clean" payment processing | Accepts cryptocurrency and untraceable payments |

    | Abuse ticket disregard | Ignores DMCA and law enforcement takedown requests |

    | DDoS-protected infrastructure | Protects hosting from vigilante or law enforcement disruption |


    Attack types facilitated by ML.Cloud and Media Land:


  • Phishing campaigns — credential harvesting targeting specific organizations
  • Distributed Denial-of-Service (DDoS) attacks — high-volume traffic flooding to disable targets
  • Brute-force attacks — automated password guessing against exposed services
  • Ransomware operations — hosting C2 infrastructure and ransom payment portals
  • Cybercrime marketplaces — platforms where threat actors bought, sold, and traded stolen data and attack tools

  • The services functioned as neutral infrastructure providers from the operators' perspective — they did not discriminate between customer types. Profit-driven ransomware gangs (motivated by direct financial theft), state-sponsored groups (motivated by intelligence gathering or disruptive operations), and individual cybercriminals all relied on the same backend systems.


    ## Investigation and Unsealing


    The indictment was returned in December 2024 but remained sealed for seven months. The decision to unseal now follows the late 2025 sanctions announcement by the United States and allied nations, suggesting coordination between law enforcement and the Treasury Department's sanctions regime.


    That two-phase approach — sanctions followed by criminal charges — is deliberate. Sanctions freeze assets and isolate targets from legitimate financial systems, while criminal prosecution establishes legal grounds for extradition and demonstrates commitment to accountability. The timing also allows law enforcement to share investigative findings with other agencies and international partners before public disclosure.


    ## Implications for Organizations


    The unsealing of these charges carries several signals for defending organizations:


    1. Hosting infrastructure remains a critical attack vector. Many organizations invest heavily in endpoint defenses and intrusion detection, but overlook the hosting and C2 infrastructure that attackers rely on. Takedown efforts are limited when operators span multiple countries and maintain redundancy.


    2. Sanctions are slow-moving. The gap between the services' actual operation and sanctions (several years) highlights enforcement delays. Organizations cannot assume that known criminal infrastructure will be disrupted quickly.


    3. Shared vulnerability. The breadth of attacks (phishing, DDoS, brute-force, ransomware) indicates these platforms supported the entire criminal supply chain. A single hosting provider amplified attacks across multiple threat models, meaning a single defensive failure could expose organizations to any attack type.


    4. Attribution complexity. Bulletproof hosting services obscure threat actor attribution. Investigators must trace traffic, payment flows, and infrastructure interdependencies to connect specific attacks to specific groups — work that is time-consuming and often incomplete.


    ## Recommendations


    For Security Leaders:


  • Assume attribution uncertainty. Attacks traced to ML.Cloud or Media Land infrastructure may originate from various actors. Treat indicators of compromise (IoCs) from these services as shared infrastructure signatures, not group-specific signatures.
  • Monitor bulletproof hosting announcements. Subscribe to law enforcement and threat intelligence updates on new bulletproof hosting takedowns and sinkhole operations. Coordinate with peers to share observed artifacts.
  • Review ransomware incident response plans. If your organization was targeted through this infrastructure, response timelines may differ from typical incidents (more threat actor redundancy, potential resiliency).

  • For Policy and Law Enforcement:


  • Accelerate international cooperation on hosting infrastructure. Many bulletproof hosts operate via jurisdictional sprawl deliberately. Coordinated action across US, EU, and allied nations is necessary.
  • Extend sanctions to financial intermediaries. Cryptocurrency exchanges and payment processors remain critical bottlenecks for bulletproof hosting operators; targeting their banking relationships amplifies sanctions impact.

  • ---


    ## HackWire Analysis


    This indictment underscores a painful reality: bulletproof hosting is a solved criminal business problem. Despite years of law enforcement disruption, takedowns, and international sanctions, the market for resilient, censorship-resistant infrastructure persists — and operators face minimal extradition risk if based outside US reach.


    The real significance of this case isn't the charges themselves (prosecution of foreign nationals is largely symbolic), but the *seven-month gap between indictment and unsealing*. That delay suggests coordinated strategy: seal the charges, build international case evidence, announce sanctions, THEN unseal to maximize diplomatic and financial pressure. This isn't justice-system-as-usual; it's multi-agency signaling.


    What's missing from coverage: the infrastructure itself may have already migrated. Bulletproof hosting isn't a company; it's a practice. Experienced operators responded to late 2025 sanctions by rotating infrastructure, payment processors, and operational security long before July charges hit the press. Law enforcement is naming yesterday's services to disrupt today's — a game of perpetual lag.


    For defenders, the lesson is blunt: bulletproof hosting will not disappear through prosecution alone. Organizations must assume advanced threat actors retain reliable C2 infrastructure regardless of takedowns. Invest in detecting infrastructure-agnostic indicators: unusual outbound traffic patterns, anomalous DNS queries, and behavioral shifts in targeted systems — not just IoC lists that become stale weeks after announcement.


    The $10 million reward is real, but the operators know it. Operational security for bulletproof hosting centers on *compartmentalization*. Low-level administrators often don't know who owns the company or where financial flows go. That structural design protects operators from bounty hunters and whistleblowers — a problem law enforcement has yet to solve.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)